VYPR

AC7

by Tenda

CVEs (70)

  • CVE-2025-3346HigApr 7, 2025
    risk 0.58cvss 8.8epss 0.07

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument pptp_server_start_ip/pptp_server_end_ip leads to buffer overflow.…

  • CVE-2026-4974HigMar 27, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to…

  • CVE-2025-11586HigOct 10, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2025-11528HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQos. The manipulation of the argument enable leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2025-11527HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform/fast_setting_pppoe_set. Executing a manipulation of the argument Password can lead to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2025-11526HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/WifiMacFilterSet. Performing a manipulation of the argument wifi_chkHz results in stack-based buffer overflow. The attack may be initiated remotely. The exploit…

  • CVE-2025-11525HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2025-11524HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be…

  • CVE-2025-9023HigAug 15, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-5862HigJun 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be initiated remotely. The…

  • CVE-2025-4810HigMay 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument reboot_time leads to stack-based buffer overflow. The…

  • CVE-2025-4809HigMay 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSafeSetMacFilter of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch…

  • CVE-2025-1851HigMar 3, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-48826HigOct 28, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.

  • CVE-2024-48825HigOct 28, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.

  • CVE-2024-32281HigApr 17, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.

  • CVE-2024-2903HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2024-2902HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. The manipulation of the argument shareSpeed leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2024-2901HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-2900HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. This affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. It is…